A limited-permission Kubernetes user can potentially gain full control of a Google Cloud organization by exploiting the Google Kubernetes Config Connector. The vulnerability represents a classic confused deputy problem in cloud infrastructure.
Security researchers at Varonis have identified a critical privilege escalation path stemming from how Kubernetes Config Connector handles permissions. The connector grants broad authority to manage GCP resources, creating a gap between what individual Kubernetes users are permitted to do and what their actions can ultimately affect.
An attacker with basic Kubernetes access could craft a malicious YAML file that, when processed by Config Connector, executes privileged GCP operations. Since the connector operates with elevated permissions in the underlying Google Cloud organization, it can perform actions the original user cannot.
This confused deputy scenario allows the attacker to bypass normal permission boundaries. The vulnerability affects organizations using Kubernetes Config Connector without sufficiently restrictive role-based access controls.
Varonis recommends implementing least-privilege principles for Config Connector deployments and auditing YAML file sources. Organizations should also monitor for suspicious resource modifications at the GCP organization level.
A threat actor is deploying open-source AI agent frameworks to compromise hundreds of online retailers at scale, harvesting over 600,000 credit card records through payment skimmers.
Enterprise infrastructure management systems are under sustained attack, with critical vulnerabilities being exploited before or immediately after vendor patches become available, according to a new InfraTrust report.
Comma's hands-off driving technology is being investigated following at least two fatal crashes. The inquiry involves instances where drivers were operating modified versions of Comma's software.
Sweden's data privacy regulator IMY has fined IT systems provider Miljödata $183,000 for inadequate security measures that led to a data breach in August 2025. The incident exposed personal information of 2.2 million individuals.